#23981 [Asn->Csd]: bcompiler doesn't check the return value of php_stream_open_wrapper()

From: Date: Fri, 06 Jun 2003 09:03:06 +0000
Subject: #23981 [Asn->Csd]: bcompiler doesn't check the return value of php_stream_open_wrapper()
References: 1  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-17108@lists.php.net to get a copy of this message
ID: 23981 Updated by: alan_k@php.net Reported By: per at nobolt dot com -Status: Assigned +Status: Closed Bug Type: PEAR related Operating System: Debian GNU/Linux PHP Version: 4.3.2 Assigned To: alan_k New Comment: thanks - added to release + a few more checks that should help.. Previous Comments: ------------------------------------------------------------------------ [2003-06-03 07:33:34] spam at nobolt dot com This bug is very serious since it causes segmentation faults on every missing file in include(), require() etc. (since bcompiler hooks into the Zend core). This patch will fix it: Index: bcompiler.c =================================================================== RCS file: /repository/pear/PECL/bcompiler/bcompiler.c,v retrieving revision 1.39 diff -u -r1.39 bcompiler.c --- bcompiler.c 8 Apr 2003 07:59:44 -0000 1.39 +++ bcompiler.c 3 Jun 2003 12:29:51 -0000 @@ -215,6 +215,10 @@ BCOMPILER_DEBUG(("no bz2 support - opening it..\n")); stream = php_stream_open_wrapper(file_name, "rb", ENFORCE_SAFE_MODE | REPORT_ERRORS, NULL); + if (!stream) { + return stream; + } + /* Sanity check to see if it is a bzip2 encoded stream */ php_stream_read(stream, magic, sizeof(magic)); if (memcmp(magic, "BZ", 2) == 0) { The only problem with this patch is that you get the warning about the missing file twice, but IMO that's much better than a segmentation fault. ------------------------------------------------------------------------ [2003-06-03 06:35:42] per at nobolt dot com In the bz2_aware_stream_open(), there is code like this: BCOMPILER_DEBUG(("no bz2 support - opening it..\n")); stream = php_stream_open_wrapper(file_name, "rb", ENFORCE_SAFE_MODE | REPORT_ERRORS, NULL); /* Sanity check to see if it is a bzip2 encoded stream */ php_stream_read(stream, magic, sizeof(magic)); If the call to php_stream_open_wrapper() fails (which it will if the file does not exist), stream will be NULL and this will cause a segmentation fault in php_stream_read(). This can easily be fixed by just checking the return value; if it is NULL, return from the function immediately. ------------------------------------------------------------------------ -- Edit this bug report at http://bugs.php.net/?id=23981&edit=1

« previous php.pear.dev (#17108) next »